Finra CARDS data breach risk is real

Potential security risk concerns over Finra's highly-debated data collection proposal are not unfounded, experts say. <i>(See also: <a href=&quot;http://www.investmentnews.com/article/20150504/BLOG07/150509984/finras-longtime-critics-become-its-supporters-and-vice-versa&quot; target=&quot;_blank&quot;>Finra's backers are now its critics</a>)</i>
APR 29, 2015
Potential security risk concerns over Finra's highly-debated Comprehensive Automated Risk Data System proposal, or CARDS, are not simply hot air, cybersecurity and big data experts say. The initiative by the Financial Industry Regulatory Authority Inc., which was recently put on hold for further evaluation amid negative feedback, was proposed as a means of collecting and analyzing broker-dealer client data. Finra's stated goal for CARDS is to catch fraudulent activity early. A spokesman for Finra said that although the self regulator will not move forward with the present form of the proposal, it is "conducting additional analyses, engaging third-party experts to further analyze these threats and exploring alternative approaches." One of the biggest criticism against the proposal is that with high volumes of data being transferred between firms and regulators, the danger of security breaches increases. “Any time you're moving private data, you have an opportunity for it to be intercepted,” said Brian Edelman, chief executive of Financial Computer Services, a company that works primarily in cybersecurity. Lowell Putnam, chief executive of Quovo, a big data company, agreed. “Any time you have large amounts of data changing hands there are risks, especially anything done on a regular schedule,” Mr. Putnam said. “The same security holes can be exploited.” ACCESS TO CLIENT DATA With CARDS, Finra would gain access to reams of client data, which historically has been monitored by brokerages. Data would include a client's investment time horizon, objectives, risk tolerance and net worth, but no personally identifiable information such as birth dates or Social Security numbers. CARDS would be an improvement from the current paper-based system because there would be no time lag, according to Barbara Roper, director of investor protection at Consumer Federation of America. “CARDS allows for an immediate process of information so warning flags can go up,” Ms. Roper said. “It allows a much quicker response by regulators when problems emerge.” Ms. Roper, who supports the proposal, said brokers have just as great a risk of cybersecurity breaches as regulators would have with CARDS with the use of data collection. “Firms believe it is worthwhile to take that risk because it's a necessity of doing business in the modern world,” she said. “We believe it is a necessity of regulating the modern world.” “There's no way to design a foolproof system, but you can't let that paralyze you, just like there's no way to design a foolproof system at the firm level,” she added. A draft of what the data record layout would look like for firms that Finra released in October includes 30 tabs of information that brokers would have to upload.

Source: Finra

Sid Yenamandra, chief executive of Entreda, a cyber-security and risk management company, said Finra could counter the cybersecurity risk argument by employing best practices for handling big data such as using encryption to transfer data, having vulnerability tests and auditing any third-party vendors that may be involved. And the self regulator could also ease opponents' minds by openly discussing where the data will be housed, how it will be integrated with firms and what the policies and procedures would be, he added. “This is all good in theory, but I think practice will determine how this will unfold and who will implement this and what the strength of that system will be,” Mr. Yenamandra said. “It's not something that's going to happen overnight.”

Latest News

The 2025 InvestmentNews Awards Excellence Awardees revealed
The 2025 InvestmentNews Awards Excellence Awardees revealed

From outstanding individuals to innovative organizations, find out who made the final shortlist for top honors at the IN awards, now in its second year.

Top RIA Cresset warns of 'inevitable' recession amid tariff uncertainty
Top RIA Cresset warns of 'inevitable' recession amid tariff uncertainty

Cresset's Susie Cranston is expecting an economic recession, but says her $65 billion RIA sees "great opportunity" to keep investing in a down market.

Edward Jones joins the crowd to sell more alternative investments
Edward Jones joins the crowd to sell more alternative investments

“There’s a big pull to alternative investments right now because of volatility of the stock market,” Kevin Gannon, CEO of Robert A. Stanger & Co., said.

Record RIA M&A activity marks strong start to 2025
Record RIA M&A activity marks strong start to 2025

Sellers shift focus: It's not about succession anymore.

IB+ Data Hub offers strategic edge for U.S. wealth advisors and RIAs advising business clients
IB+ Data Hub offers strategic edge for U.S. wealth advisors and RIAs advising business clients

Platform being adopted by independent-minded advisors who see insurance as a core pillar of their business.

SPONSORED Compliance in real time: Technology's expanding role in RIA oversight

RIAs face rising regulatory pressure in 2025. Forward-looking firms are responding with embedded technology, not more paperwork.

SPONSORED Advisory firms confront crossroads amid historic wealth transfer

As inheritances are set to reshape client portfolios and next-gen heirs demand digital-first experiences, firms are retooling their wealth tech stacks and succession models in real time.